Courseiva

LFCS Operation of Running Systems Practice Question

A system administrator notices that a web server process (PID 1234) is consuming excessive CPU. They want to trace its system calls to identify the cause. Which command should be used?

⚠ Common exam trap

Watch out — candidates often confuse `strace` (system calls) with `ltrace` (library calls), as both trace function calls but at different layers of the software stack, leading them to pick the wrong tool for kernel-level analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

strace -p 1234

The correct command is `strace -p 1234`, which attaches to the running process (PID 1234) and intercepts all system calls (e.g., read, write, open) made by that process. This allows the administrator to see exactly what the web server is doing at the kernel level, such as excessive file I/O or network operations, which can pinpoint the cause of high CPU usage. Other tools like ltrace, perf, or gdb serve different purposes (library calls, profiling, debugging) and do not directly trace system calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ltrace -p 1234

    Why it's wrong here

    ltrace intercepts library calls such as malloc or printf, not the kernel syscalls the process issues, so it cannot reveal the syscall causing CPU load. It is tempting because it also uses ptrace and prints call traces, but it is the right tool for diagnosing shared-library or userspace function behaviour.

  • ✗

    perf record -p 1234

    Why it's wrong here

    perf record samples hardware and software events for profiling, producing statistical call-graph data rather than a syscall-by-syscall trace, so it cannot name the specific syscalls being invoked. It is tempting because it diagnoses CPU hotspots, but it is correct for performance profiling, not syscall tracing.

  • ✗

    gdb -p 1234

    Why it's wrong here

    Debugger, not a system call tracer.

  • ✓

    strace -p 1234

    Why this is correct

    strace attaches to a running process via -p and reports each system call it makes, exposing where PID 1234 spends time in kernel operations. This directly addresses tracing syscalls of an existing high-CPU process without restarting it.

About these practice questions

Courseiva writes every LFCS question from scratch — 406 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This LFCS practice question is part of Courseiva's free Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LFCS exam.